UbuntuUpdates.org

Package "libowasp-esapi-java"

Name: libowasp-esapi-java

Description:

Enterprise Security API (ESAPI)

Latest version: 2.4.0.0-2ubuntu0.1
Release: noble (24.04)
Level: updates
Repository: universe
Homepage: https://github.com/esapi/esapi-java-legacy

Links


Download "libowasp-esapi-java"


Other versions of "libowasp-esapi-java" in Noble

Repository Area Version
base universe 2.4.0.0-2
security universe 2.4.0.0-2ubuntu0.1

Changelog

Version: 2.4.0.0-2ubuntu0.1 2026-04-16 22:08:41 UTC

  libowasp-esapi-java (2.4.0.0-2ubuntu0.1) noble-security; urgency=medium

  * SECURITY UPDATE: Improper SQL special-element neutralization
    - debian/patches/CVE-2025-5878.patch: Deprecate SQL encodings in
      src/main/java/org/owasp/esapi/Encoder.java,
      src/main/java/org/owasp/esapi/codecs/DB2Codec.java,
      src/main/java/org/owasp/esapi/codecs/MySQLCodec.java,
      src/main/java/org/owasp/esapi/codecs/OracleCodec.java and
      src/main/java/org/owasp/esapi/reference/DefaultEncoder.java
    - CVE-2025-5878

 -- Shafayat Hossain Majumder <email address hidden> Wed, 15 Apr 2026 13:35:40 -0400

CVE-2025-5878 A vulnerability was found in ESAPI esapi-java-legacy and classified as problematic. This issue affects the interface Encoder.encodeForSQL of the SQL



About   -   Send Feedback to @ubuntu_updates